ControlMapping for SOC2 (CC6.1, CC6.6, CC6.7, CC4.1, CC7.x), PCI-DSS (8.3.9, 8.6.3, 10.5.x, 3.7.4), ISO 27001:2022 (A.5.16, A.5.17, A.5.18, A.8.5, A.8.15, A.8.16, A.8.24), HIPAA (164.308 / 164.312). Mapping is intentionally minimal - each event maps only where it provides direct evidence. Bundle.write produces a self-verifying ZIP: - audit_log.ndjson (raw chain rows with hex hashes) - audit_batches.json (signed Merkle roots) - control_mapping.json (event_type -> controls) - manifest.json (per-file SHA-256 + size) - README.md (verification instructions) - public_key.pem + manifest.sig (Ed25519, when signer provided) 7 specs verify ZIP layout, manifest sha256-per-file, control mapping content per framework. |
||
|---|---|---|
| .. | ||
| .github/workflows | ||
| spec | ||
| src | ||
| .editorconfig | ||
| .gitignore | ||
| LICENSE | ||
| Makefile | ||
| README.md | ||
| shard.lock | ||
| shard.yml | ||
README.md
Credential Rotation Enforcer (cre)
A Crystal-based daemon that tracks and enforces credential rotation
policies across AWS Secrets Manager, HashiCorp Vault, GitHub fine-grained
PATs, and local .env files.
Full README, asciinema demos, and walkthrough live in
learn/. This README will be expanded in Phase 16 of the build.